| URL: | http://cobalten.com/afu.php?zoneid=1219810 |
| Full analysis: | https://app.any.run/tasks/39c4c407-b315-4a59-b883-0dccf372b26e |
| Verdict: | Malicious activity |
| Analysis date: | March 12, 2021, 14:51:43 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | EC9895F0EADB144DB3D4E658A42EC629 |
| SHA1: | 2672142479E6A6E2569C0C6EEDCAC308284FAACC |
| SHA256: | 75306903C494F233C6313F37A15FCAB65A461735DF7CDEEE04F10B3E7FE1A7DB |
| SSDEEP: | 3:N1KdKHBd0Mhz1zFSn:CIhiMhzbS |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 120 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1048,14727057842427939105,13423792494668888535,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=11730611779660720959 --renderer-client-id=20 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4896 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 592 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1048,14727057842427939105,13423792494668888535,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=8446194523680564280 --renderer-client-id=10 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3708 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1092 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1048,14727057842427939105,13423792494668888535,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=14071689798702071844 --renderer-client-id=19 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4856 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1604 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1048,14727057842427939105,13423792494668888535,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=449683852352288737 --mojo-platform-channel-handle=4308 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1736 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1048,14727057842427939105,13423792494668888535,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=8159270375811365182 --renderer-client-id=8 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2808 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1832 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=75.0.3770.100 --initial-client-data=0x7c,0x80,0x84,0x78,0x88,0x6c23a9d0,0x6c23a9e0,0x6c23a9ec | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 2140 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1048,14727057842427939105,13423792494668888535,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgACAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=1943446599701740935 --mojo-platform-channel-handle=1020 --ignored=" --type=renderer " /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 2180 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1048,14727057842427939105,13423792494668888535,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=15631376380624751370 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2176 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 2340 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1048,14727057842427939105,13423792494668888535,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=13961212311535352997 --mojo-platform-channel-handle=4240 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 2348 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1048,14727057842427939105,13423792494668888535,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=7260545337741806843 --renderer-client-id=21 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4344 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| (PID) Process: | (3420) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | write | Name: | 2988-13260034319140125 |
Value: 259 | |||
| (PID) Process: | (2988) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (2988) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (2988) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (2988) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (2988) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (2988) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (2988) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (2988) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 3252-13245750958665039 |
Value: 0 | |||
| (PID) Process: | (2988) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2988 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-604B800F-BAC.pma | — | |
MD5:— | SHA256:— | |||
| 2988 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\0545066b-72b1-4f9d-92a7-875aa6ce82f3.tmp | — | |
MD5:— | SHA256:— | |||
| 2988 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000048.dbtmp | — | |
MD5:— | SHA256:— | |||
| 2988 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2988 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RFd8b77.TMP | text | |
MD5:— | SHA256:— | |||
| 2988 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RFd8b77.TMP | text | |
MD5:— | SHA256:— | |||
| 2988 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2988 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2988 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2988 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RFd8d6b.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2748 | chrome.exe | GET | 200 | 34.96.99.173:80 | http://imptrk.siteplug.com/impTrk.php?enk1=513db8e25fe9c737cb18a5752563cb0d0d747337cba71ca0bc0c1767430be6b0bd4183ad2be08603c11a4539c265514945c886fb5f7184fc6845bb452e760f1e4212c2ca210f16d5d996f34ca7d3c4a40ce3e92c0ff59c3d2ffdc9b691e93bc8&enk2=d646714913aba435ffd0f01f410b174c22bd07ffdfa5272f4edda1a4d55ef99a3464f594299233172faa14c6680085ca06f0993c6cd8d31217e955e1ced60e5f9eafd64cc3206e4e79ffcd4e5fd5c13b406cbfb120efbc360e7e2ec43da154d0692521adffe20500f3096521e2898d490a5b92be383905e9f5ea5f8bfca08012d8e3440ba1ae864fa10fd3dee49b3e7ca23020b8ef63a03cbab25bcff2f9462fbbd06955a0228b96624088d3c99c3f60&ccd=it&stc=mi&cin=milano&mcd=0&cic=104266&kw=qldummy | US | — | — | suspicious |
2748 | chrome.exe | GET | 200 | 34.96.99.173:80 | http://imptrk.siteplug.com/impTrk.php?enk1=513db8e25fe9c737cb18a5752563cb0d0d747337cba71ca0bc0c1767430be6b0bd4183ad2be0860314a4fbe71a3cbaf945c886fb5f7184fc6845bb452e760f1e4212c2ca210f16d5d996f34ca7d3c4a40ce3e92c0ff59c3d9ef916f1f320c74a&enk2=d646714913aba435ffd0f01f410b174c22bd07ffdfa5272f9a19c5304b625957671f0d2262468739ffa998a856ca062806f0993c6cd8d31217e955e1ced60e5fba91e711c92e95da79ffcd4e5fd5c13b406cbfb120efbc360e7e2ec43da154d0692521adffe20500f3096521e2898d490a5b92be383905e9f5ea5f8bfca08012d8e3440ba1ae864fa10fd3dee49b3e7cb101bfd55851ef5685b769248b8db03bbbd06955a0228b96624088d3c99c3f60&ccd=it&stc=mi&cin=milano&mcd=0&cic=104266&kw=qldummy | US | — | — | suspicious |
2748 | chrome.exe | GET | 200 | 34.96.99.173:80 | http://imptrk.siteplug.com/impTrk.php?enk1=513db8e25fe9c737cb18a5752563cb0d0d747337cba71ca0bc0c1767430be6b0bd4183ad2be08603d4957f757577a62345c886fb5f7184fc6845bb452e760f1e4212c2ca210f16d5d996f34ca7d3c4a40ce3e92c0ff59c3d4c13c1e79bc2d95b&enk2=d646714913aba435ffd0f01f410b174c22bd07ffdfa5272fc27bb95ba7e6b3f8919e674a8f6c928ae612567f70ed8c4c4a870139462ca0d36286d42571c5e61a2776b6e29a4d4121907313f37cb1a69857abd5647e883aae007a48b4fc29f0a09b5f29666d444a21901d200b15525ae2003c2c01c588ee2c34ed88176a48785124a3038b3d03cd1e9d60ee23f41c80e0d0c25a2ddc09e368aa3024fe2cb4a029f4637d7ec7c0c4c0&ccd=it&stc=mi&cin=milano&mcd=0&cic=104266&kw=qldummy | US | — | — | suspicious |
2748 | chrome.exe | GET | 200 | 34.96.99.173:80 | http://imptrk.siteplug.com/impTrk.php?enk1=513db8e25fe9c737cb18a5752563cb0d0d747337cba71ca0bc0c1767430be6b0bd4183ad2be08603ad8073df4406660445c886fb5f7184fc6845bb452e760f1e4212c2ca210f16d5d996f34ca7d3c4a40ce3e92c0ff59c3d87490b546c81138d&enk2=d646714913aba435ffd0f01f410b174c22bd07ffdfa5272fb5f699f8cc05710581007ce2c4951366bd9f17ee369d09fc06f0993c6cd8d31217e955e1ced60e5f476d8249a063a1c879ffcd4e5fd5c13b406cbfb120efbc360e7e2ec43da154d0692521adffe20500f3096521e2898d490a5b92be383905e9f5ea5f8bfca08012d8e3440ba1ae864fa10fd3dee49b3e7cf245a7fc07d3b4d6bbb874bec00eed42bbd06955a0228b96624088d3c99c3f60&ccd=it&stc=mi&cin=milano&mcd=0&cic=104266&kw=qldummy | US | — | — | suspicious |
2748 | chrome.exe | GET | 200 | 34.96.99.173:80 | http://imptrk.siteplug.com/impTrk.php?enk1=513db8e25fe9c737cb18a5752563cb0d0d747337cba71ca0bc0c1767430be6b0bd4183ad2be086035ca71983e786eab145c886fb5f7184fc6845bb452e760f1e4212c2ca210f16d5d996f34ca7d3c4a40ce3e92c0ff59c3dea4169019ed648c1&enk2=d646714913aba435ffd0f01f410b174c22bd07ffdfa5272f8c533da835c60c6ef77017dd4e7a17fa7014c211b037df4e06f0993c6cd8d31217e955e1ced60e5fa23088a9a97e81d579ffcd4e5fd5c13b406cbfb120efbc360e7e2ec43da154d0692521adffe20500f3096521e2898d490a5b92be383905e9f5ea5f8bfca08012d8e3440ba1ae864fa10fd3dee49b3e7ca23020b8ef63a03c85b769248b8db03bbbd06955a0228b96624088d3c99c3f60&ccd=it&stc=mi&cin=milano&mcd=0&cic=104266&kw=qldummy | US | — | — | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2748 | chrome.exe | 139.45.197.240:80 | propeller-tracking.com | — | US | unknown |
2748 | chrome.exe | 95.217.204.250:443 | adtrackingflow.pro | Hetzner Online GmbH | DE | unknown |
2748 | chrome.exe | 139.45.197.239:443 | bainushe.com | — | US | malicious |
2748 | chrome.exe | 104.21.85.191:443 | install.pdfsearchweb.com | Cloudflare Inc | US | unknown |
2748 | chrome.exe | 139.45.197.240:443 | propeller-tracking.com | — | US | unknown |
2748 | chrome.exe | 172.67.208.220:443 | get.rsjpm.com | — | US | malicious |
2748 | chrome.exe | 139.45.195.8:443 | my.rtmark.net | — | US | suspicious |
2748 | chrome.exe | 104.16.18.94:443 | cdnjs.cloudflare.com | Cloudflare Inc | US | unknown |
2748 | chrome.exe | 216.58.212.170:443 | fonts.googleapis.com | Google Inc. | US | whitelisted |
2748 | chrome.exe | 69.16.175.10:443 | b6u2w2z4.ssl.hwcdn.net | Highwinds Network Group, Inc. | US | malicious |
Domain | IP | Reputation |
|---|---|---|
cobalten.com |
| malicious |
accounts.google.com |
| shared |
propeller-tracking.com |
| whitelisted |
my.rtmark.net |
| whitelisted |
adtrackingflow.pro |
| unknown |
bainushe.com |
| suspicious |
get.rsjpm.com |
| unknown |
install.pdfsearchweb.com |
| malicious |
fonts.googleapis.com |
| whitelisted |
b6u2w2z4.ssl.hwcdn.net |
| malicious |